{
  "id": "CMP-124",
  "slug": "cmp-124",
  "title": "A multi-step consent flow must be captured at every step",
  "statement": "Where consent is collected across several screens, evidence must show each step rather than the final one.",
  "rationale": "In a multi-step flow the disclosure and the consent control are usually on different screens, so a screenshot of the step carrying the button proves nothing about what was disclosed before it. This is the flow shape where a compliant programme most often looks non-compliant — everything required was shown, and the evidence only covers the last screen of it.",
  "layer": "CAMPAIGN",
  "layerSlug": "campaign",
  "object": "opt-in screenshots",
  "severity": "HIGH",
  "detectability": [
    "VISION"
  ],
  "failureClass": "TERMINAL_EVIDENCE",
  "authorities": [
    "Twilio",
    "LeadConnector",
    "optinfix"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30917",
      "remediable": true
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Capture every screen between arriving and consenting, in order, and combine them into one PDF. Done when the sequence shows the disclosure and the consent act without a gap a reviewer has to fill in.",
  "example": "A three-page PDF: the product page with the offer, the form with the phone field and disclosure, the confirmation screen after submitting.",
  "catalogIds": [
    "CON-032"
  ],
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/campaign/cmp-124/",
  "markdown": "https://ekas.io/rules/10dlc/campaign/cmp-124.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
